CVE-2025-11113: Codeastro Online Leave Application

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was detected in CodeAstro Online Leave Application 1.0. Affected is an unknown function of the file /signup.php. Performing manipulation of the argument city results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used. Other parameters might be affected as well.

Affected products

  • Codeastro Online Leave Application: version 1.0 only

Published 2025-09-28. Last modified 2026-10-09.